Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-182282956
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Android 安全漏洞
Vulnerability Description
Google Android是美国谷歌(Google)公司的的一套以Linux为基础的开源操作系统。 Google Android 存在安全漏洞,该漏洞源于 BluetoothPairingDialog 的 onCreate 中,由于窃听/覆盖攻击,有一种可能无需用户同意即可启用蓝牙的方法。 这可能导致需要用户执行权限的本地权限提升。 漏洞利用需要用户交互。
CVSS Information
N/A
Vulnerability Type
N/A